In July 2026, an AI model built by OpenAI broke out of a test environment and hacked into a real company, Hugging Face. Both companies have confirmed it happened, and outside investigators, including CrowdStrike, are now reviewing the incident.
No person was directing the attack step by step. The AI worked it out on its own. That’s the part worth paying attention to, because it’s the first clear sign that AI systems can be the ones doing the hacking, not just a tool a human attacker uses.
Pharmacies weren’t the target this time. But they’re already one of the most heavily attacked types of business in Australia, so it’s worth asking what this shift means for them.
Pharmacies are already a target in Australia
A few recent examples show this isn’t hypothetical:
- MediSecure (2024): the prescription delivery system used across Australian pharmacies was breached, exposing health information linked to around 12.9 million people.
- Outback Pharmacies (2025): a regional NSW pharmacy group had 150GB of patient data stolen by a ransomware gang.
- Partnered Health (2026): 21 medical clinics across five states had patient records stolen.
Healthcare is already the most breached sector in Australia, and phishing is the most common way attackers get in. None of that required AI. The concern now is that AI makes the same kind of attack faster and easier to pull off at scale.
What AI changes
A human attacker has to plan and execute each step of a hack. An AI agent can do this on its own, much faster. In tests, AI agents have moved through company systems in under two hours, and most businesses already using AI agents have had at least one security incident because of them.
The Hugging Face case shows how this plays out. The AI escaped its test environment, found its way onto the internet, then broke into a real company’s systems, all without a human directing each move.
For a pharmacy, this raises a few practical risks:
- Better fake emails and texts. AI can write convincing messages that look like they’re from a supplier or head office.
- Faster exploitation of outdated software. Unpatched dispensing or point-of-sale systems become easier targets.
- Risk through suppliers. An attack doesn’t need to start at the pharmacy. A compromised supplier or software provider can be the way in.
- Quieter breaches. Attackers are increasingly stealing data without locking systems, so there may be no obvious sign anything happened.
How to protect your business
The good news is that the basics still work, whether the attacker is a person or an AI. The Australian Cyber Security Centre’s Essential Eight is the standard starting point for small businesses, and it comes down to a handful of practical habits:
- Keep software patched and up to date, especially anything connected to the internet, like dispensing or point-of-sale systems.
- Use multi-factor authentication on every important system, ideally with a passkey or security key rather than SMS codes.
- Limit admin access so one compromised login can’t take down the whole system.
- Back up your data properly, and store backups somewhere a hacker can’t reach with the same login as everything else.
- Train staff on AI-style scams. Poor spelling isn’t a reliable warning sign anymore, so teach staff to double-check unusual requests another way, like a phone call.
- Check your suppliers’ security, not just your own, since their breach can become your problem.
- Know your reporting obligations. Data breaches need to be reported to the OAIC, and there are separate rules for ransomware under the Cyber Security Act.
- Have a plan ready so you know who to call and what to do the moment something looks wrong, rather than figuring it out during an actual incident.
The bottom line
An AI system finding and using a security gap its own creators didn’t know about is a real turning point. But the fundamentals of good cyber security, patching, backups, MFA and staff awareness, still work regardless of who or what is doing the attacking. Getting those basics right matters more than trying to keep pace with the technology itself.
Sources
This article draws on incident disclosures from OpenAI and Hugging Face, reporting from Reuters, Time, MIT Technology Review, TechCrunch and CNBC, industry research from Darktrace, Comparitech and Sophos, Australian breach reporting on MediSecure, Outback Pharmacies and Partnered Health, OAIC Notifiable Data Breaches reports, and ACSC Essential Eight guidance, all current as of early August 2026.
Written by Phoenix Nguyen, Systems Manager – AP Group
AP Group are the leading pharmacy experts in Australia, helping hundreds of pharmacists into ownership every year – our team can help with sourcing finance for your purchase, as well as providing the right legal advice to help you navigate the process.
We connect existing pharmacy owners with over 5000 ready and eager investors via our cutting-edge online Data Room. Our Data Room keeps confidential listing data secure and allows buyers to make informed decisions on each of our pharmacies for sale.
About the Author:

When you picture an IT consultant, you probably don’t picture a keen surfer, fisherman and family man firing up the BBQ. But, that’s Phoenix. He also knows how to come up with savvy IT solutions that improve our productivity and efficiency — so that’s rather handy.
With over 18 years IT experience in various sectors across Australia, Asia and the USA, Phoenix knows his way around a computer. His speciality lies in developing and implementing IT solutions for front-end and back-end development, social media, CRM systems, ERP systems and infrastructure upgrades.
More than that, Phoenix has an impressive work history, advising leading companies like Sony, CH1, Macquarie Group, Fast Retailing CO and Jetstar. Today, what he loves most about his role at AP Group is the team — it’s like one big happy family.
